CVE-2025-23195
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 611
Summary
CVE-2025-23195 is a newly discovered XML External Entity (XXE) vulnerability affecting the Ambari/Oozie project. This issue arises due to insecure parsing of XML input using the `DocumentBuilderFactory` class, which fails to disable external entity resolution. An attacker can exploit this vulnerability by injecting malicious XML entities, potentially leading to arbitrary file reading or Server-Side Request Forgery (SSRF) attacks. The vulnerability has been addressed in Ambari 2.7.9 and the trunk branch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.